Experts warn that ChatGPT’s Workspace Agent Builder can be hijacked to create malicious AI workers


  • Zenity Labs discovered AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder
  • Malicious links could instantly deploy malicious agents that exfiltrate sensitive data without prompting from the user.
  • OpenAI fixed the issue by removing the risky URL parameter; no abuse detected

AI agents come in handy for responding to customer emails or tracking reports on recently released security vulnerabilities. But what if they go rogue and turn against the company they’re supposed to support?

Security researchers at Zenity Labs have found a way for cybercriminals to trick people into deploying such agents in their own tech stack. Since it only takes a single click, the disruptive potential of these attacks is arguably far greater than anything a phishing attack could do.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top